Privacy Policy
Last updated: August 6, 2026
Voxylis ("we", "us", "our") is committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679) and other applicable data protection laws.
1. Data Controller
The data controller responsible for your personal data is Voxylis, reachable via our Discord server or support ticket system. For GDPR inquiries, contact us through the official channels listed in Section 12.
2. Personal Data We Collect
We collect and process the following categories of personal data:
- Identity & Contact Data: Name or username, email address, and any information you provide when creating an account or contacting support.
- Transaction Data: Purchase history, product keys issued, payment method type (but not full card numbers — these are processed solely by our PCI-DSS compliant payment processors).
- Technical Data: IP address, browser type and version, device type, operating system, referring URLs, and time zone settings. This is collected automatically when you visit our Site.
- Usage Data: Pages visited, products viewed, time spent on pages, and interaction patterns. This helps us improve our Services.
- Communication Data: Any information you provide when communicating with us via Discord, support tickets, or other channels.
3. Legal Basis for Processing (GDPR Art. 6)
We process your personal data only when we have a lawful basis:
- Contractual Necessity (Art. 6(1)(b)): Processing necessary to fulfill your purchase, deliver digital goods, and provide account access.
- Legal Obligation (Art. 6(1)(c)): Retaining transaction records for tax and accounting purposes as required by EU and national law.
- Legitimate Interests (Art. 6(1)(f)): Improving our Services, preventing fraud, ensuring network security, and responding to support inquiries. We balance our interests against your rights and freedoms.
- Consent (Art. 6(1)(a)): Where required, we will ask for your explicit consent — for example, for marketing emails or non-essential cookies. You may withdraw consent at any time.
4. How We Use Your Data
We use your personal data to:
- Process and deliver your orders for Digital Goods.
- Create and manage your account.
- Send order confirmations, delivery emails, and invoices.
- Provide customer support and respond to inquiries.
- Detect, prevent, and address fraud, abuse, and security incidents.
- Comply with legal obligations (tax, accounting, regulatory).
- Improve and optimize our Site and Services (analytics).
We do not sell, rent, or trade your personal data to third parties for marketing purposes. We do not engage in automated decision-making or profiling that produces legal effects concerning you.
5. Data Sharing & Third-Party Processors
We share your data only as necessary with the following categories of recipients:
- Payment Processors: Stripe, PayPal, and cryptocurrency payment gateways — for processing payments. These providers are PCI-DSS compliant and act as independent data controllers for payment data.
- Hosting & Infrastructure: Our hosting provider and CDN services — for website delivery and security.
- Analytics: We may use privacy-focused analytics to understand site usage.
- Legal Authorities: Where required by law, court order, or to protect our legal rights.
All third-party processors are bound by data processing agreements (DPAs) ensuring GDPR-compliant handling of your data.
6. International Data Transfers
If your data is transferred outside the European Economic Area (EEA), we ensure adequate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission or reliance on adequacy decisions. Contact us for details on specific transfer safeguards.
7. Data Retention
We retain your personal data only as long as necessary:
- Account Data: Retained while your account is active, plus 3 years after last activity for legal claims.
- Transaction Data: Retained for 10 years (or as required by applicable tax and accounting laws).
- Support Communications: Retained for 3 years after resolution.
- Technical/Usage Data: Retained in anonymized or pseudonymized form for up to 26 months.
8. Your GDPR Rights
As an EU/EEA resident, you have the following rights:
- Right of Access (Art. 15): Request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete data.
- Right to Erasure — "Right to be Forgotten" (Art. 17): Request deletion of your data where no legitimate reason for continued processing exists.
- Right to Restriction (Art. 18): Request limited processing in certain circumstances.
- Right to Data Portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format and have it transmitted to another controller.
- Right to Object (Art. 21): Object to processing based on legitimate interests, including profiling.
- Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time without affecting the lawfulness of prior processing.
- Right to Complain (Art. 77): Lodge a complaint with your national Data Protection Authority (DPA).
To exercise any of these rights, contact us via our support channels. We will respond within one month (extendable by two months for complex requests, with notification). Identification verification may be required.
9. Cookies & Tracking
Our Site uses cookies and similar technologies. We distinguish between:
- Essential Cookies: Necessary for the functioning of the Site (session management, cart, security). These do not require consent under GDPR but are disclosed here for transparency.
- Non-Essential Cookies: Analytics and preference cookies. These are placed only after you provide explicit consent via our cookie banner. You can manage or withdraw consent at any time via your browser settings.
For detailed cookie information, see our Cookie Declaration available on the Site.
10. Data Security
We implement appropriate technical and organizational measures (TOMs) to protect your personal data, including:
- End-to-end encryption (TLS 1.3) for all data in transit.
- Encrypted storage for data at rest.
- Access controls and least-privilege principles.
- Regular security assessments and monitoring.
- PCI-DSS compliant payment processing (card data never touches our servers).
While we strive to protect your data, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
11. Children's Privacy
Our Services are not directed to individuals under the age of digital consent in their country (typically 16 in the EU). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us immediately for deletion.
12. Contact & DPA
For privacy-related inquiries, GDPR rights requests, or to report a data breach concern:
- Open a support ticket via your account dashboard.
- Contact us through our official Discord server.
You have the right to lodge a complaint with your local Data Protection Authority. A list of EU DPAs is available at the European Data Protection Board website.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to registered users via email or prominent notice on the Site. The "Last updated" date at the top indicates when this policy was last revised.